A network control that blocks packets with forged source IP addresses from entering or leaving a network. For DNS amplification, this matters because spoofing is what lets attackers redirect large resolver responses toward a chosen victim.
What Source Address Filtering Does
Source address filtering is a basic network hygiene control: it verifies whether packets arriving on an interface should plausibly carry the source IP address they claim. When that check fails, the network drops the traffic instead of forwarding it.
That sounds simple, but it matters because source IP spoofing is an enabling condition for several abuses, especially when an attacker wants to hide where traffic came from or make packets appear to originate from elsewhere. The control is therefore less about authenticating a sender and more about refusing obviously inconsistent network-layer provenance.
Why It Matters for Abuse Prevention
Its most visible value is in limiting spoofed traffic from crossing a trust boundary. If an edge device allows packets with impossible or unexpected source addresses, downstream systems may see traffic that is harder to attribute, harder to rate-limit, and easier to use in reflection or amplification abuse.
For DNS amplification in particular, spoofing is the key enabler because the attacker forges the victim’s address as the source of the request, then uses open resolvers to send much larger replies to the victim. Source address filtering removes one of the easiest ways to launch that pattern from networks that enforce it properly.
It also supports operational clarity. Logs, flow records, and incident investigations are more trustworthy when the network rejects traffic that claims to come from an address block that should never appear on that interface or from a direction where that source is not routable.
Where It Is Applied
Source address filtering is usually implemented at network ingress and, in some designs, at egress. Ingress filtering blocks external packets whose source addresses do not match the expected routing or interface context; egress filtering prevents internal hosts from emitting packets with forged source addresses into the broader internet.
The exact enforcement point depends on the network architecture. ISPs, enterprise edges, cloud gateways, and routed segmentation boundaries can all apply the idea, but the underlying goal is the same: stop packets from using a source address that the path or policy says should not be there.
The control is strongest when it is aligned with routing reality, interface role, and address allocation. If the policy is too loose, spoofed traffic slips through; if it is too rigid or outdated, legitimate traffic can be dropped and cause operational issues.
Limits and Common Misconceptions
Source address filtering is not a substitute for authentication, encryption, or application-layer authorization. It only addresses whether the claimed source address is plausible at the network boundary, not whether the sender is trusted or whether the payload is safe.
It also does not stop every abuse case that involves spoofing. Attackers may still use networks that do not enforce filtering, or they may rely on relays, compromised infrastructure, or abuse paths that bypass the edge where filtering is strongest.
The control is best understood as one of the lowest-friction ways to reduce spoofing at scale. Its value comes from blocking an entire class of malformed or deceptive traffic early, before higher-cost monitoring or response logic has to sort it out.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-4 — System Monitoring | Network spoofing reduction supports monitoring and detection of anomalous traffic flows. |
| AC-4 — Information Flow Enforcement | Filtering forged source addresses enforces allowed network information flows at boundaries. | |
| SC-7 — Boundary Protection | Source address filtering is a boundary protection control against spoofed external traffic. | |
| Recommendation — Correlate rejected spoofed packets with SI-4 alerts to spot abuse patterns and boundary failures. Apply AC-4 at ingress and egress boundaries to block traffic with implausible source addresses. Use SC-7 boundary enforcement to drop packets whose source addresses do not match path expectations. | ||
| CIS Controls v8 | CIS-13 — Network Monitoring and Defense | Spoofing defense is part of network defense and traffic validation at boundaries. |
| Recommendation — Monitor boundary traffic for spoofed-source indicators and block them in your network defense stack. | ||
| MITRE ATT&CK | T1036 — Masquerading | Source IP spoofing is a masquerading technique used to disguise traffic origin. |
| Recommendation — Map spoofed-source traffic to T1036 and hunt for traffic that impersonates an unexpected origin. | ||